CyberRota Analysis
AI-GeneratedThe OpenClaw Feishu tools npm package allows unauthorized operations due to a flaw in its authorization checks, particularly affecting versions up to 2026.6.6. This vulnerability could be exploited by lower-trust callers or through misconfigured input paths, leading to potential unauthorized access or actions. Organizations using this package, especially those with sensitive configurations, should prioritize upgrading to version 2026.6.9 to mitigate the risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configured input path could perform actions that should have required a stronger authorization or policy check, resulting in unauthorized operations. The issue is fixed in version 2026.6.9. Impact depends on the operator's configuration and whether lower-trust input can reach the affected feature.
Related CVEs
Other vulnerabilities affecting the same vendor(s)